Exposed Task Object in Kestra Orchestration Platform by Kestra
CVE-2026-73246
7.5HIGH
What is CVE-2026-73246?
The Kestra orchestration platform, prior to version 2.0.0-rc6, contains a vulnerability where the WorkerEndpoint exposes a GET endpoint without authentication. This flaw allows unauthorized access to the live Task object, inadvertently revealing sensitive information such as command details, environment variables, HTTP headers, connection specifications, plaintext credentials, and execution identifiers. Despite the protection on the main API monitoring port 8080, the lack of secure access to this endpoint could lead to significant security risks for users.
Affected Version(s)
kestra < 1.3.31
